MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 4 h ago, last 4 h ago, peak #7

Storm-3168 Wiped Azure Resources Using Stolen Service Principals

Original: 🤖 Storm-3168/JADEPUFFER abused compromised Azure service principals to run destructive operations — deleting resources o

The threat actor tracked as Storm-3168, associated with the JADEPUFFER campaign, abused compromised Azure service principals to carry out destructive operations, deleting cloud resources over roughly 18 hours in early June 2026. Microsoft assesses the activity as an evolution of the actor's tradecraft, and security teams are being urged to review service principal permissions.

Why now: Microsoft's assessment of an evolving cloud attack technique has prompted security practitioners to warn about service principal abuse and destructive Azure operations.

Storm-3168MicrosoftAzureJADEPUFFER

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/227874